Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 18 of 48
CVE-2017-0596P3HIGHCVSS 7.8v4.4.4v5.0.2+5 more2017-05-12
CVE-2017-0596 [HIGH] CVE-2017-0596: An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malici
An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2017-0410P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+4 more2017-02-08
CVE-2017-0410 [HIGH] CWE-190 CVE-2017-0410: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2017-0546P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-04-07
CVE-2017-0546 [HIGH] CWE-476 CVE-2017-0546: An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application
An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Ve
nvd
CVE-2017-0480P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0480 [HIGH] CVE-2017-0480: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2016-6705P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+3 more2016-11-25
CVE-2016-6705 [HIGH] CWE-264 CVE-2016-6705: An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5
An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated c
nvd
CVE-2016-6740P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6740 [HIGH] CWE-264 CVE-2016-6740: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30143904. References: Qualcomm QC-CR#1056307.
nvd
CVE-2016-6741P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6741 [HIGH] CWE-264 CVE-2016-6741: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30559423. References: Qualcomm QC-CR#1060554.
nvd
CVE-2016-6738P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6738 [HIGH] CWE-264 CVE-2016-6738: An elevation of privilege vulnerability in the Qualcomm crypto engine driver in Android before 2016-
An elevation of privilege vulnerability in the Qualcomm crypto engine driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30034511. References: Qualcomm QC-CR#105053
nvd
CVE-2017-0597P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0597 [HIGH] CWE-190 CVE-2017-0597: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0479P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0479 [HIGH] CVE-2017-0479: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2016-6739P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6739 [HIGH] CWE-264 CVE-2016-6739: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30074605. References: Qualcomm QC-CR#1049826.
nvd
CVE-2016-6737P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6737 [HIGH] CWE-264 CVE-2016-6737: An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 cou
An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair
nvd
CVE-2016-3904P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-3904 [HIGH] CWE-264 CVE-2016-3904: An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 coul
An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30311977. References: Qualcomm QC-CR#1050455.
nvd
CVE-2016-8433P3HIGHCVSS 7.8vn/a2017-01-12
CVE-2016-8433 [HIGH] CWE-264 CVE-2016-8433: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious applic
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Vers
nvd
CVE-2017-0604P3HIGHCVSS 7.8vn/a2017-05-12
CVE-2017-0604 [HIGH] CWE-670 CVE-2017-0604: An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local mal
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product:
nvd
CVE-2016-10274P3HIGHCVSS 7.8vn/a2017-05-12
CVE-2016-10274 [HIGH] CWE-264 CVE-2016-10274: An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local mali
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product:
nvd
CVE-2017-13252P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13252 [HIGH] CWE-787 CVE-2017-13252: In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input valida
In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-7052
nvd
CVE-2018-9458P3HIGHCVSS 7.8vAndroid-8.0 Android-8.12018-11-06
CVE-2018-9458 [HIGH] CWE-1021 CVE-2018-9458: In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interc
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the screen was locked with no additional execution privileges needed. User interaction is needed for explo
nvd
CVE-2015-9014P3CRITICALCVSS 9.8vAndroid kernel2018-04-04
CVE-2015-9014 [CRITICAL] CWE-264 CVE-2015-9014: An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Vers
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.
nvd
CVE-2016-8482P3HIGHCVSS 7.8vAndroid kernel2018-04-05
CVE-2016-8482 [HIGH] CWE-264 CVE-2016-8482: An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Androi
An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.
nvd